Re: parse_str() patch

From: Date: Mon, 11 Sep 2000 20:21:46 +0000
Subject: Re: parse_str() patch
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-32957@lists.php.net to get a copy of this message
But I need register_globals to be on for other stuff. The point of my patch was so that I could process the string without polluting the local variable space. I will look into trying to create a patch based on the 4.0.3-dev version that will fulfill my needs, unless you want to take a crack at that instead. -John On Mon, 11 Sep 2000, Stanislav Malyshev wrote: > JB>> The version of the patch in 4.0.3-dev puts variables into the local > JB>> variable space even if the output array is passed into the function. If > JB>> you use parse_str() and give it the output array, you don't need the > JB>> variables to be set in the local space, and in some cases, this is even > JB>> undesirable. > JB>> > JB>> Imagine: You are using parse_str() to evaluate a string with untrusted > JB>> content. Someone could maliciously feed you a string that overwrites your > JB>> variables with their content. > > Then you need to unset register_globals. Maybe I'll make some patch to do > it, but what your patch did was really wrong (name[] didn't work and there > were more problems with that). > > -- > Stanislav Malyshev stas@zend.com http://www.zend.com/ > > +972-3-6139665 ext.106 > > > -- > PHP Development Mailing List <http://www.php.net/> > To unsubscribe, e-mail: php-dev-unsubscribe@lists.php.net > For additional commands, e-mail: php-dev-help@lists.php.net > To contact the list administrators, e-mail: php-list-admin@lists.php.net > > -- John Bafford dshadow@zort.net http://www.dshadow.com/

« previous php.dev (#32957) next »